📦 Central Authentication Service

by Apereo

🔍 What is Central Authentication Service?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-4399

CRITICAL CVSS 9.1 May 23, 2024

This vulnerability allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF) attacks by exploiting improper input validation in a parameter before making requests. It affects syst...

CVE-2023-4612

CRITICAL CVSS 9.8 Nov 9, 2023

CVE-2023-4612 is an authentication bypass vulnerability in Apereo CAS that allows attackers to circumvent Multi-Factor Authentication by manipulating the remote address in HTTP requests. This affects ...

CVE-2025-3986

MEDIUM CVSS 4.3 Apr 27, 2025

This vulnerability in Apereo CAS 5.2.6 involves inefficient regular expression complexity in the CasConfigurationMetadataServerController.java file, allowing remote attackers to cause denial of servic...

CVE-2025-3984

MEDIUM CVSS 5.0 Apr 27, 2025

This critical vulnerability in Apereo CAS 5.2.6 allows remote attackers to execute arbitrary code through the Groovy Code Handler component. The vulnerability exists in the saveService function and en...

CVE-2024-11209

MEDIUM CVSS 6.3 Nov 14, 2024

This vulnerability in Apereo CAS 6.6 allows attackers to bypass two-factor authentication (2FA) on the /login?service endpoint, potentially leading to unauthorized access. It affects systems using the...